FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
Article Id 352830
Description This article describes how to search FortiAnalyzer Threats Logs in Log View.
Scope FortiAnalyzer.

Consider the following scenario:


In FortiAnalyzer, view the Top Threats information. Go to FortiView -> Threats -> Top Threats.


202410_FAZ check threats logs_01.PNG


Double-click it to view more information.


202410_FAZ check threats logs_02.PNG


Copy the syntax from Top Threats and paste it into Log View to get the related log information.


202410_FAZ check threats logs_03.PNG